BTCPay Server Vulnerability Drains Funds from Connected Lightning Nodes
A critical vulnerability in BTCPay Server's handling of Lightning node credentials allowed attackers to drain funds from connected nodes, affecting at least two prominent Bitcoin community members. The flaw, which persisted even after users applied software updates, gave unauthorized access to macaroons, API keys that grant permission to perform actions on a Lightning node.
The issue was separate from a prior authentication bug that BTCPay Server had already patched just days earlier. The project released an urgent security alert on August 7, recommending that operators update to version 2.4.2 or shut down their servers entirely to prevent further losses.
Foundation, the company behind hardware wallets, and hodlonaut, who runs Citadel21, reported that their Lightning channels were force-closed and funds swept clean. Their associated hot wallets were not affected, indicating a specific vulnerability in BTCPay Server's handling of Lightning node authentication.